What Is SMB1001 Certification? A Plain-English Guide for NZ Business Owners

If you run a business with 20 to 200 staff in New Zealand, there is a good chance a client, insurer, or tender document has asked you about SMB1001 in the last few months. Here is what it actually is, in plain English, before you decide whether to chase it.

What Is SMB1001, Exactly?

SMB1001 is a tiered cyber security certification standard built specifically for small and medium businesses, not large corporates with dedicated security teams. It was developed by Dynamic Standards International (DSI) and is certified through the CyberCert platform. The standard started in Australia and is used on both sides of the Tasman: New Zealand businesses certify through the same CyberCert platform as Australian ones, and nothing in the standard depends on Australian legislation.

It is not a marketing badge. Each tier maps to a specific set of technical, process, people and insurance controls. At the lower tiers a company director personally attests that the controls are in place; at the higher tiers an independent auditor checks. Either way, SMB1001 is designed to be something you can prove, not just claim.

IT technician configuring network security controls in a small business server cupboard

Watch: SMB1001 Certification Explained

Prefer the short version? Here is a plain-English overview of SMB1001, the five tiers from Bronze to Diamond, and how it compares to ISO 27001 and the Essential Eight.

SMB1001 certification explained (1 min 38 sec).

The Five Tiers, From Bronze to Diamond

SMB1001 has five tiers, each building on the one below it:

  • Bronze — the fundamentals: passwords, multi-factor authentication, patched software, basic backups.
  • Silver — adds structured processes: vulnerability assessments, managed firewalls, staff security awareness training.
  • Gold — the tier most insurers and larger customers actually check for: endpoint detection and response, enforced email authentication, mandatory cyber insurance and a tested incident response plan.
  • Platinum and Diamond — advanced tiers requiring independent external audit rather than director attestation, aimed at businesses with more mature security programmes.

You do not have to climb the ladder one rung at a time. Most NZ businesses we talk to go straight for Gold, because it is the first tier that satisfies insurance underwriters and enterprise procurement teams. Our complete guide to SMB1001 Gold certification breaks down the full cost, the 27 controls, who signs it off, and how the 90-day path works.

Printed SMB1001 controls checklist beside a laptop showing a security controls diagram

Why SMB1001 Is Gaining Traction in NZ in 2026

Three things are driving demand right now. Larger organisations are asking their vendors and supply chain partners for proof of cyber security controls, and SMB1001 answers that in one document instead of a forty-question spreadsheet. Cyber insurers are tightening underwriting and increasingly want evidence of MFA, endpoint protection and a formal framework before they will offer cover. And the Privacy Act 2020 keeps getting tested, with breaches reported more often and the reputational cost of a breach travelling fast.

The threat numbers back it up. CERT NZ, now part of the National Cyber Security Centre, has consistently reported phishing and business email compromise among the top incident types hitting NZ small businesses. Attackers are not only going after big corporates: the accounting firm, the logistics company, and the local retailer down the road all hold valuable data with far less formal security than an enterprise IT department.

Two colleagues reviewing a cyber security controls dashboard on a tablet in a meeting room

Do I Need This If I'm a Small Business?

Yes, often more than a large one. SMB1001 was built specifically for small and medium businesses because they tend to hold valuable client data without the formal controls of a large enterprise, which makes them a target rather than a business too small to bother with. A tiered path means you are not expected to jump straight to enterprise-grade security. You start at the level that matches your risk and grow from there.

Small retail business owner working in her shop, an everyday example of the businesses SMB1001 was built for

SMB1001 vs ISO 27001 vs Essential Eight: Which Do I Need?

Short answer: for most NZ businesses under 200 staff, SMB1001 is the practical first certification. ISO 27001 is a full information security management system with external audits, usually only required when enterprise or government contracts demand it. The Essential Eight is a set of technical mitigation strategies from the Australian Signals Directorate with no certificate attached. We compare all three in detail, including cost and timeframes, in our SMB1001 vs ISO 27001 guide.

Why Businesses Fail Their First SMB1001 Assessment

The most common failure point is not a missing technical control. It is documentation. A business can have MFA enforced, backups running and endpoint protection in place, and still stall at assessment because none of it is written down as policy. SMB1001 asks you to prove your controls, not just run them: written policies, training records, and an incident response plan that exists on paper rather than in the heads of your team.

The second trap is treating certification as a one-off. The standard is updated as threats change, so controls that passed last year may need a refresh at renewal. Both problems disappear if the documentation is written as the controls go in and the annual renewal is planned as a review rather than a restart. That is most of what a structured programme actually does.

Where to Start

The path is the same regardless of which tier you are aiming for:

  1. Gap assessment. Map your current environment against the controls for the tier you need.
  2. Close the priority gaps. Technical controls first, then policies, training and insurance.
  3. Attest or audit, then certify. A director attests for Bronze, Silver and Gold; Platinum and Diamond require an independent audit.

OxygenIT has operated from Christchurch since 2005, holds ISO 27001 and ISO 42001 certification ourselves, and takes NZ businesses to SMB1001 Gold in 90 days as part of our IT compliance service. See what that costs on our SMB1001 pricing page, or book a discovery call and we will map your environment against the standard. Call us on 0800 101 095.

Frequently Asked Questions

What is SMB1001 certification?

SMB1001 is a tiered cyber security certification standard for small and medium businesses, developed by Dynamic Standards International and certified through the CyberCert platform. It covers five tiers, Bronze through Diamond, each requiring a specific set of technical, process and insurance controls that a director attests to or an auditor verifies.

Is SMB1001 the same as ISO 27001 or the Essential Eight?

No. SMB1001 is a certifiable standard built specifically for small and medium businesses. ISO 27001 is a broader information security management system with external audits, and the Essential Eight is a set of technical mitigation strategies with no certificate attached. They are complements rather than substitutes for each other.

Does a small business really need SMB1001, or is it just for large companies?

Small businesses need it just as much, sometimes more. SMB1001 was designed around the reality that small businesses hold valuable data without a large IT team behind them. The tiered structure means you start at Bronze if that is where your business sits today, rather than being measured against an enterprise standard.

How much does SMB1001 certification cost?

Cost depends on the tier and your current security maturity. The CyberCert certificate fee itself ranges from about AUD $195 at Silver to several thousand dollars at Platinum, and implementation on top of that varies by business. Our SMB1001 pricing page lists the fees and packages by tier.

What is the first step to getting SMB1001 certified?

A gap assessment against the controls for your target tier. That tells you exactly what is already in place and what needs work before you can attest or certify, and turns the standard into a fixed price and a timeline rather than an open-ended project.

How long does SMB1001 certification take?

It depends on the tier and where you start. Bronze can be done in days if the fundamentals are already in place. Gold typically takes about 90 days with a structured programme: gap assessment first, then closing the technical and documentation gaps, then director sign-off and certification.

What is the biggest reason businesses fail their first SMB1001 assessment?

Missing documentation. Many businesses have solid technical controls but no written policies, training records or tested incident response plan to prove them. SMB1001 checks that you can evidence your controls, so the paperwork counts as much as the technology.

Can I get SMB1001 certified without hiring an IT company?

Yes. Nothing in the standard requires an external provider, and at the lower tiers a capable internal person can implement the controls and write the policies. Most businesses bring in a partner for Gold because the control set is larger and the evidence requirements are stricter, and a provider that has already mapped the controls saves weeks of guesswork.

What do I have to do if my business has a data breach?

If the breach could cause serious harm, the Privacy Act 2020 requires you to notify the Office of the Privacy Commissioner and the people affected as soon as practicable. Failing to report can lead to fines of up to 10,000 dollars, on top of the reputational cost. An incident response plan and enforced email authentication, both SMB1001 controls, are built specifically to reduce this risk.

How much can a data breach cost a small business in New Zealand?

Costs vary widely, but once you add investigation, legal advice, customer notification and lost business on top of the immediate technical fix, a breach commonly runs into the tens or hundreds of thousands of dollars for a small business. The exact figure depends on how much data was involved and what kind. It is one of the clearest financial arguments for pairing certification with cyber insurance.

Let’s transform your business with our reliable IT solutions!